WAT: Improve the Worst-class Robustness in Adversarial Training

02/08/2023
by   Boqi Li, et al.
0

Deep Neural Networks (DNN) have been shown to be vulnerable to adversarial examples. Adversarial training (AT) is a popular and effective strategy to defend against adversarial attacks. Recent works (Benz et al., 2020; Xu et al., 2021; Tian et al., 2021) have shown that a robust model well-trained by AT exhibits a remarkable robustness disparity among classes, and propose various methods to obtain consistent robust accuracy across classes. Unfortunately, these methods sacrifice a good deal of the average robust accuracy. Accordingly, this paper proposes a novel framework of worst-class adversarial training and leverages no-regret dynamics to solve this problem. Our goal is to obtain a classifier with great performance on worst-class and sacrifice just a little average robust accuracy at the same time. We then rigorously analyze the theoretical properties of our proposed algorithm, and the generalization error bound in terms of the worst-class robust risk. Furthermore, we propose a measurement to evaluate the proposed method in terms of both the average and worst-class accuracies. Experiments on various datasets and networks show that our proposed method outperforms the state-of-the-art approaches.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
05/29/2021

Analysis and Applications of Class-wise Robustness in Adversarial Training

Adversarial training is one of the most effective approaches to improve ...
research
02/17/2023

Revisiting adversarial training for the worst-performing class

Despite progress in adversarial training (AT), there is a substantial ga...
research
05/30/2023

It begins with a boundary: A geometric view on probabilistically robust learning

Although deep neural networks have achieved super-human performance on m...
research
08/01/2023

Doubly Robust Instance-Reweighted Adversarial Training

Assigning importance weights to adversarial data has achieved great succ...
research
05/26/2019

Robust Classification using Robust Feature Augmentation

Existing deep neural networks, say for image classification, have been s...
research
12/02/2019

Fastened CROWN: Tightened Neural Network Robustness Certificates

The rapid growth of deep learning applications in real life is accompani...
research
06/05/2020

Principled Learning Method for Wasserstein Distributionally Robust Optimization with Local Perturbations

Wasserstein distributionally robust optimization (WDRO) attempts to lear...

Please sign up or login with your details

Forgot password? Click here to reset